CodamAIDocs
Topicdone

Which events are logged

Which events go into the audit trail: registration, user, consent to a user switch, tenant, role grant.

Variants
RegistrationEventUserEventSwitchConsentEventTenantEventAuthorizationEvent

What this is about

Every event that a CIAS module reports goes into the audit. The events are arranged in five groups, one per module, two for cias-user. In the audit an entry is named by group and kind, such as UserEvent.Suspended.

The five groups

The events per module

When: cias-registration, in the course of a registration

Initiated (request accepted, email sent; with flow), Verified (link clicked), Completed (provisioned; with Keycloak ID and tenant), Rejected (rejected; with reason), Failed (provisioning failed; with reason), Expired (cleaned up; with last state and whether the account was deleted).

Result: See The states of a registration

When: cias-user, in user management

Recorded (user record created; with Keycloak ID and home tenant), Activated (enabled or reactivated), Suspended (suspended; with reason), Closed (closed; with reason), Moved (moved to another home tenant; from, to), PasswordSetupLinkSent (password link sent; with address, without the link).

Result: See The lifecycle of a user

When: cias-user, around the consent for a user switch

Requested (consent requested; who, whom, mode, end, reason), Granted (consent given, directly or by approving a request), Declined (request declined), Revoked (consent revoked or request withdrawn; with who revoked it), FirstUsed (consent used for the first time). Each with consent ID, both persons and tenant.

Result: See User switch by header

When: cias-tenancy, in the lifecycle of a tenant

Created (created), Activated (in service, also after provisioning), Suspended (suspended), Resumed (resumed), Closed (closed), ProvisioningFailed (setup failed; with reason). Each with ID and key of the tenant.

Result: See The lifecycle of a tenant

When: cias-authorization, for role grants

Granted (granted; with end date and grantedBy), Revoked (revoked; with revokedBy and reason), Expired (end date reached), Activated (start of a scheduled grant reached), WindowChanged (window changed when the same role was granted again). Each with grant ID, person, client, role and tenant.

Result: See Grant a role and Time-limited roles

All events in one table

Entry in the auditOccasionRecords
RegistrationEvent.Initiatedregistration acceptedID, flow
RegistrationEvent.Verifiedaddress confirmedID
RegistrationEvent.Completedregistration finishedID, Keycloak ID, tenant
RegistrationEvent.RejectedrejectedID, reason
RegistrationEvent.Failedprovisioning failedID, reason
RegistrationEvent.Expiredexpired registration cleaned upID, state, account removed yes/no
UserEvent.Recordeduser record createduser ID, Keycloak ID, home tenant
UserEvent.Activateduser activeuser ID
UserEvent.Suspendeduser suspendeduser ID, reason
UserEvent.Closeduser closeduser ID, reason
UserEvent.Movedhome tenant changeduser ID, old and new tenant
UserEvent.PasswordSetupLinkSentpassword link sentuser ID, address
SwitchConsentEvent.Requestedconsent for a user switch requestedconsent ID, requesting person, target person, tenant, mode, end, reason
SwitchConsentEvent.Grantedconsent givenconsent ID, both persons, tenant, mode, end, whether on request, reason
SwitchConsentEvent.Declinedrequest declinedconsent ID, both persons, tenant
SwitchConsentEvent.Revokedconsent revoked or request withdrawnconsent ID, both persons, tenant, who revoked
SwitchConsentEvent.FirstUsedconsent used for the first timeconsent ID, both persons, tenant, mode
TenantEvent.Createdtenant createdtenant ID, key
TenantEvent.Activatedtenant in servicetenant ID, key
TenantEvent.Suspendedtenant suspendedtenant ID, key
TenantEvent.Resumedtenant resumedtenant ID, key
TenantEvent.Closedtenant closedtenant ID, key
TenantEvent.ProvisioningFailedsetup failedtenant ID, key, reason
AuthorizationEvent.Grantedrole grantedgrant, person, role, tenant, end date, grantedBy
AuthorizationEvent.Revokedrole revokedgrant, person, role, tenant, revokedBy, reason
AuthorizationEvent.Expiredtime-limited role expiredgrant, person, role, tenant
AuthorizationEvent.Activatedscheduled role beginsgrant, person, role, tenant
AuthorizationEvent.WindowChangedwindow of a running grant changedgrant, person, role, tenant, start, end, who, reason

No event contains a link, a token or a password. PasswordSetupLinkSent names the address, not the link.

What reports no event

The audit only contains what a module reports as an event. These actions report none and are therefore not in the audit:

  • creating, changing, deleting groups, adding and removing members
  • creating, retiring or deleting roles in the catalog, and the reconciliation with Keycloak. What a reconciliation did is in its report
  • writing attribute values, in the profile or per tenant
  • changing a tenant’s validity period
  • renaming a user or replacing their CIAS attributes. When existing accounts are imported, a UserEvent.Recorded is created per account
  • saving and deleting mail templates. Who changed it last is in updatedBy on the template
  • tenant and user switches by header, that is every single switched request. Of the user switch, only the first use of a consent is in the audit, see above
  • logging in, logging out, renewing the token. Keycloak keeps track of that

Pitfalls

Next

Sources in the code and the knowledge base
  • CIAS/cias-registration – api.RegistrationEvent (Initiated, Verified, Completed, Rejected, Failed, Expired)
  • CIAS/cias-user – api.UserEvent (Recorded, Activated, Suspended, Closed, Moved, PasswordSetupLinkSent), UserService
  • CIAS/cias-user – api.SwitchConsentEvent (Requested, Granted, Declined, Revoked, FirstUsed), SwitchConsentService
  • CIAS/cias-tenancy – api.TenantEvent (Created, Activated, Suspended, Resumed, Closed, ProvisioningFailed), TenantService
  • CIAS/cias-authorization – api.AuthorizationEvent (Granted, Revoked, Expired, Activated, WindowChanged), RoleAssignmentService
  • CIAS/cias-kernel – DomainEvent; CIAS/cias-audit – DomainEventAuditListener
  • CIAS/cias-audit/docs/adr – ADR-033
Search